Security and Trust Center
Security and Trust Center
Security
Compliance
Privacy
Security and Resilience by Design
Corporate Security & Resilience
Organizational Resilience
Supply Chain Resilience
Protecting Products, Prioritizing Customers
Secure Manufacturing and Shipping
Consumer and Enterprise Security Against Fraud
Security Vulnerability Policy
Secure Product Development
Personnel Risk Management
Industry Collaboration
Security Advisories

Approved Product List
Vendor | Model | Version | Effective Date | Expiration Date | APL Product Category | Certified Device Types | Links |
Dell | PowerScale OneFS | 9.5 | June 12, 2023 | June 12, 2026 | Data Storage Controller (DSC) | PowerScale OneFS F200 Cluster | |
Dell | EMC Unity Family | OE 5.2 | March 14, 2018 | March 14, 2024 | Data Storage Controller (DSC) | 300, 300F, 350F, 400, 400F | APL Memo - APL Memo Original IO Cert - 2/2/18 DTR#1 8/10/18 DTR#2 4/30/19 DTR#3 9/18/19 DTR#4 12/21/20 DTR#5 7/19/21 DTR#6 5/23/22 |
Dell | EMC PowerMax Array and Management User Interface (UI) | 10 | June 29, 2021 | June 29, 2024 | Data Storage Controller (DSC) | PowerMax 2000 Array | APL Memo - APL Memo Original IO Cert - 6/24/21 DTR#1 4/19/22 DTR#2- 10/13/22 |
Dell | EMC Networking PowerSwitch S4100 and S5200 Series, and S4248FB-ON, N3245TE-ON, N3248TE-ON, and E3224F-ON Switches | SmartFabric OS 10.5 | December 19, 2019 | December 19, 2025 | Assured Services Local Area Network (ASLAN), Access IP Switch, Distribution IP Switch, Core IP Switch | S4112F-ON, S4112T-ON | APL Memo - APL Memo Original IO Cert - 12/18/19 DTR#1 7/20/21 DTR#3 9/27/22 DTR#4 11/3/22 |
Dell | EMC Networking PowerSwitch | SmartFabric OS 10.5 | December 19, 2019 | December 19, 2025 | Assured Services Local Area Network (ASLAN), Access IP Switch, Distribution IP Switch, Core IP Switch | Z9264F-ON | APL Memo APL Memo Original IO Cert 12/18/19 DTR#1 4/9/20 DTR#2 8/3/21 DTR#3 9/19/22 DTR#4 12/9/22 |
Dell | EMC PowerEdge MX7000 | SmartFabric OS 10.5 | May 18, 2020 | May 18, 2026 | Assured Services Local Area Network (ASLAN), Access IP Switch | MX7000 | APL Memo APL Memo Original IO Cert 5/14/20 DTR#1 3/9/23 |
Dell | Power Protect Data Domain (DD) Series | Data Domain Operating System (DDOS) 8.0 | 30-Apr-24 | 30-Apr-27 | Cybersecurity Tools (CST) | DD6900 | APL Memo APL Memo Original IO Cert 5/11/23 DTR#1 2/22/24 DTR#2 3/28/24 |

Common Criteria Compliance
Name | Assurance Level | Certification Date | Expiration Date | Links |
XtremIO | EAL2+, ALC_FLR.2 | | | Scheme CA |
Dell EMC SRM | EAL2+, ALC_FLR.2 | | | Scheme CA |
Recoverpoint for Virtual Machines | EAL2+, ALC_FLR.2 | | | Scheme CA |
Networker | EAL2+, ALC_FLR.2 | | | Scheme CA Type Products in evaluation |
Integrated Data Protection Appliance (IDPA) v2.6 | EAL2+, ALC_FLR.2 | | | Scheme CA |
Dell Data Protection Encryption Personal Edition Version 10.8 | PP_APP_V1.3, MOD_FE_V1.0 | | | Scheme CA Type Products in evaluation |
Dell EMC™ VxFlex 3.0.1.208 | EAL2+, ALC_FLR.2 | September 9, 2020 | September 09, 2025 | Certification Report Certification Report Security Target Security Target Scheme CA Type Active certifications |
Dell EMC Networking SmartFabric OS10 v10.5.1 | CPP_ND_V2.1 | September 15, 2020 | September 15, 2025 | Certification Report Certification Report Security Target Security Target Scheme CA Type Active certifications |
Dell EMC™ SupportAssist Enterprise 4.0 with Policy Manager 6.8 | EAL2+, ALC_FLR.2 | August 6, 2020 | August 06, 2025 | Certification Report Certification Report Security Target Security Target Scheme CA Type Active certifications |
Dell EMC™ VxRail™ 4.7 | EAL2+, ALC_FLR.2 | June 30,2020 | June 30, 2025 | Certification Report Certification Report Security Target Security Target Scheme CA Type Active certifications |

A UK government certification scheme in cyber security
Cyber Essentials is a UK Government-backed framework that helps protect organizations from many different cyber attacks.
Dell’s certificate certifies that the organization was assessed as meeting the Cyber Essentials implementation profile for its UK locations supporting the UK Public sector.
Download Certificate

Dell CyberGRX Assessment
Dell has completed the CyberGRX assessment, validated by CyberGRX strategic partners Deloitte and Touche and KPMG.
The CyberGRX assessment methodology identifies both inherent and residual risk and uses near real time threat analysis and independent evidence validation to provide customers with a holistic view of their third-party cyber risk posture.
The CyberGRX Risk Assessment may be requested here.

Dell Cybervadis Assessment
CyberVadis has completed an assessment of Dell Technologies corporate security environment to validate the design and implementation of controls.
CyberVadis is a scalable solution for managing third-party cybersecurity risk assessment process. CyberVadis is based on a methodology that maps to all major international compliance standards, including GDPR, NIST, NY DFS, CCPA, and many more. It combines the speed of automation with the accuracy and effectiveness of a team of experts.
To access the report, please contact your dedicated sales and service representative.
The EU Data Act is a European regulation that establishes rules on who can access and use data generated by connected devices and
digital services. Questions may be sent by email to eu.data.act@dell.com.
Supporting Documents
Data Disclosures
Data Disclosures for Connected Products or Related Services can be accessed directly on the EU Data Act In-Scope Products & Services (in English) website.
Access, Switching, & Deletion Requests
Requests can only be processed for EU Customers and must be complete before they can be processed.
Access requests are only available for Connected Products and Related Services.
Switching and Deletion Requests are only available for Data Processing Services.
To facilitate Access or Switching Requests, Request Data Access in the Dell Technologies Privacy Center and select the option for an EU Data Act request.
If you would like a third party to carry out an access request on your behalf,
please include a signed copy of the EU Data Act Third-Party Request Form with the submission.
To facilitate a Deletion Request, Request Data Deletion in the Dell Technologies Privacy Center and select the option for an EU Data Act request.

Health Information Trust Alliance
Health Information Trust Alliance (HITRUST) is a data protection standards and development certification organization designed to assist healthcare providers, business associates, and vendors in safeguarding sensitive data and managing IT risk.
HITRUST certification enables organizations to demonstrate they are taking a proactive approach to cybersecurity, data protection and risk mitigation. It provides assurance to customers, vendors, shareholders and other third parties that Dell meets high standards in information protection. HITRUST compliance is required by all major healthcare payers in the US. and is leveraged by 81 percent of US hospitals and health systems and 83 percent of health plans. It is the most widely adopted control framework in the healthcare sector.
Services in Scope:
| Offer | Assurance Level | Report Period Start | Report Period End |
| Dell-managed APEX Data Storage Services (DM-ADSS) | HITRUST E1 | January 22, 2024 | January 22, 2025 |

Infosec Registered Assessors Program
The Information Security Registered Assessors Program (IRAP) enables Australian Government customers to validate that appropriate controls are in place and determine the appropriate responsibility model for addressing the requirements of the Australian Government Information Security Manual (ISM) produced by the Australian Cyber Security Centre (ACSC).
The Dell Cloud services that have been IRAP assessed can be found in the table below. An independent IRAP assessor examined the controls including people, processes, and technology against the requirements of the ISM.
In Scope Service Offers
| Offer/Service | |
| Dell APEX Backup-as-Service Offerings |
|

Global ISO 27001 Multi-Site Certification
Dell Technologies Global ISO 27001 Multi-Site Certification is an Information Security Management System (ISMS) and encompasses activities which enable the protection of information assets across the enterprise including Dell Technology Services (DTS), Sales, Dell Financial Services (DFS), Dell Infrastructure Solutions Group (ISG) and supporting functions inclusive of the Security & Resiliency Organization (SRO); IT; Facilities Management, Human Resources and Legal, in accordance with the Statement of Applicability.

Service for Aerospace, Defence and Security Sectors
An accreditation system for the aerospace, defense and security sectors. The system was established following an initiative led by ADS Group and includes a growing number of prime contractors as registered buyers together with the MoD. JOSCAR is a cross-sector community which reduces the time, cost and resources and duplication needed to provide information to major buying organizations.
Joscar provides a risk management tool that objectively assesses potential vendor risks, proportionally to products and services being provided and across relevant areas of compliance.
This JOSCAR certificate covers all of Dells Products and Services

Dell KY3P Assessment
KY3P® Assessments* is a third-party assessment solution designed to facilitate the exchange of standardized and validated risk data between service providers and their customers.
KY3P® has completed an independent comprehensive risk assessment of Dell Technologies corporate security environment to validate the design and implementation of controls. The validation process included structured inquiries regarding design elements and specific requirements, policy, program, and procedure inspections, as well as reviews of supporting evidence. The risk assessments can be leveraged by leading financial institutions globally to accelerate vendor due diligence requirements and cloud adoption. KY3P standardizes and simplifies third party due diligence, provides end-to-end visibility and vigilance needed to protect the supply chain.
The KY3P® Dell Technologies Risk Assessment may be requested here.

Open Trusted Technologies Providers standard
The O-TTPS Certification Program is to assure customers of the integrity of commercial off-the-shelf (COTS) information and ICT products worldwide and to safeguard global supply chains against increasingly sophisticated security attacks.
Intended to assure integrity in technology development and to prevent maliciously tainted and counterfeit products from entering the supply chain, the certification program helps ensure applicants conform to the O-TTPS standard.
Demonstration of conformance through this independent, voluntary O-TTPS Certification Program process provides formal recognition of an organization’s conformance to this industry standard. Successful applicants will gain certification and can use the Open Trusted Technology Provider trademarked logo.
Dell participates in the O-TTPS Certification Program by completing a self-assessment of its compliance with O-TTPS version 1.2 (ISO/IEC 20243:2023).
Products in Scope
Client and IT Infrastructure Products from Dell Technologies, Inc.
Download Certificate here
The DSPT assessment is a mandatory requirement for all organizations that access NHS patient information. It ensures that we uphold strong information governance practices and demonstrate compliance through the publication of annual assessments. This is also a contractual obligation under the NHS England standard conditions contract, which states: “The organization must complete and publish an annual information governance assessment and must demonstrate satisfactory compliance as defined in the DSP Toolkit.”

PCI Data Security Standard
PCI Data Security Standard (PCI DSS) applies to entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD). PCI DSS is a set of security standard comprises of technical and operational requirements, developed by PCI Security Standards Council (PCI SSC) for protecting payment data. PCI Security Standards Council or SSC, which was founded by 5 major payment brands American Express, Discover, JCB International, MasterCard and Visa Inc with the purpose of developing and driving the adoption of PCI DSS.
Dell Inc. is an eCommerce Merchant and required to comply with PCI Data Security Standard (PCI DSS). We are a Level 2 Merchant and report PCI compliance status to acquirers through Self-Assessment Questionnaires (SAQ). We perform PCI DSS Assessment annually and the assessment was validated by certified PCI Internal Security Assessor (ISA). Dell Inc. is certified as a PCI DSS Level 2 Merchant.

Service Organization Control
SOC reports are governed by the American Institute of Certified Public Accountants (AICPA) and focus on offering assurance that the controls service organizations put in place to protect their clients’ assets are effective. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems the service organization uses to process users’ data and the confidentiality and privacy of the information processed by these systems.
Dell operates a centrally governed SOC program and SOC reports are specific to our Offers and Services and independently assessed and attested by PwC and Schellman Compliance.
To access the report, please contact your dedicated sales and service representative.
Services In Scope include
| Offer/Service | Assurance Level | Report Period Start | Report Period End |
| AI Ops Infrastructure Observability | Type 2 SOC 2 | October 01, 2023 | September 30, 2024 |
| Dell Automation Platform | Type 1 SOC 2 | As of August 15, 2025 | |
| Dell Managed Services Platform (DMSP) | Type 2 SOC 2 | October 01, 2023 | September 30, 2024 |
| Managed Detection & Response (MDR) | Type 2 SOC 2 | October 01, 2023 | September 30, 2024 |
| Apex AIOps Incident Management Platform | Type 2 SOC 2 | April 01, 2024 | September 30, 2024 |
| Moogsoft Hosted Platform | Type 2 SOC 2 | April 01, 2024 | September 30, 2024 |
| Remote Manages Services for Backup, Storage and Converged Infrastructure Services | Type 2 SOC 1 | October 01, 2023 | September 30, 2024 |
| Remote Manages Services for Backup, Storage and Converged Infrastructure Services | Type 2 SOC 2 | October 01, 2023 | September 30, 2024 |
| Virtustream Enterprise Cloud (VEC) | Type 2 SOC 1 | June 01, 2024 | June 30, 2025 |
| Virtustream Enterprise Cloud (VEC) | Type 2 SOC 2 | June 01, 2024 | June 30, 2025 |
| Virtustream Federal Cloud (VFC) | Type 2 SOC 1 | June 01, 2024 | June 30, 2025 |
| Virtustream Federal Cloud (VFC) | Type 2 SOC 2 | June 01, 2024 | June 30, 2025 |
| Wyse Management Suite (WMS) | Type 2 SOC 2 | December 01, 2023 | September 30, 2024 |
| Modular Managed Services (MMS) | Type 1 SOC 2 | As of December 20, 2024 |

Customer Security Program
Dell participates in Swift’s Customer Security Programme (CSP) to help financial institutions ensure their defences against cyberattacks are up to date and effective, to protect the integrity of the wider financial network. Users compare the security measures they have implemented with those detailed in the Customer Security Controls Framework (CSCF), before attesting their level of compliance annually.
With solid attestation and compliance rates, the CSP reflects a community of highly engaged users committed to stopping cyberattacks in their tracks. And, as the cyber threat landscape evolves, so too does the CSP.
You can also find more info here Customer Security Programme (CSP) | Swift

Trusted Information Security Assessment Exchange
Trusted Information Security Assessment Exchange (TISAX) is the standard to prove to the automotive industry that the information entrusted to Dell Technologies is secure and conforms to a defined level of information security requirements according to the German Association of the Automotive Industry (VDA ISA). TISAX is a registered trademark and governed by the ENX Association. The ENX portal is used as an exchange mechanism to share Dell’s assessment results with the automotive industry.
Dell’s scope ID on the ENX portal is S8R56Z. This will provide you with a summary of our overall assessment results for the Professional, Managed & Field Services teams at the following locations:
LR5M8V Dell GmbH Frankfurt am Main
LV4T3L Dell GmbH München (Ismaning) ► Main Location
L149V1 Dell GmbH Stuttgart (Leonberg)
LM9LYX Dell International Services India
LMMM29 Dell Ovens Cork
LP0LWY Dell Technologies Services Dalian
LCL6F7 Dell Egypt Service Center
Next Steps
Dell Technologies’ built-in security capabilities combined with our portfolio of products and services
-
LEARN MORE ABOUT OUR SOLUTIONS
-
Secure anywhere-work with hardware and software defenses built for today’s cloud-based world.
Learn More